Anthropic deployed Claude Mythos 5 in its Claude Security scanner, now in public beta for Enterprise customers. The move gates its most capable model to defensive use with human approval required for every patch.
Anthropic now runs Claude Security on Claude Mythos 5, scanning codebases for vulnerabilities in public beta for Enterprise customers. The rollout puts the company's most capable model behind defensive tools while keeping it out of general availability.
Key facts
- Claude Security now runs on Claude Mythos 5 in public beta
- Scans count as normal token usage for Enterprise customers
- Each finding includes CWE category, severity rating, suggested fix
- Partners protecting hospitals, utilities, and banks get Mythos 5 access
- Anthropic targets $2T+ valuation in October IPO
Anthropic has put its most capable model to work on the defensive side of cybersecurity. According to The Decoder, the company's Claude Security scanner now runs on Claude Mythos 5, available in public beta for Enterprise customers. The tool scans codebases for vulnerabilities, assigns each finding a CWE category, provides severity ratings, and suggests patches. Scans count as normal token usage, and humans must sign off on every patch before it's applied.
Anthropic is also integrating Mythos 5 into partner security products that protect hospitals, utilities, and banks. End users never interact with the model directly — they only see results like suggested patches. Several partners already use Claude Opus for security tooling and are expected to switch to Mythos 5, according to the report. Security vendors can sign up for partnership access.
Key Takeaways
- Anthropic deployed Claude Mythos 5 in its Claude Security scanner, now in public beta for Enterprise customers.
- The move gates its most capable model to defensive use with human approval required for every patch.
Why the restriction matters
The deliberate gating of Mythos 5 is the notable structural choice here. Claude Mythos is Anthropic's most capable model, especially for cyber tasks, which is why it's not broadly available, the company says. This rollout is meant to boost defenders without handing attackers new AI-powered options. That's a rare posture in an industry where frontier models typically ship to everyone at once — the same week Anthropic filed for an October IPO targeting a $2T+ valuation with projected annualized revenue of $100-120B by year-end, per the knowledge graph.
The human-in-the-loop requirement is also worth scrutinizing. Anthropic's own Claude Code with Opus 4.8 scores 88.6% on SWE-bench Verified and 69.2% on SWE-bench Pro, per prior reporting. But for security patches, the company is explicitly keeping a human gate. That suggests Anthropic considers the cost of a bad autonomous patch higher than the speed benefit — a stance that may slow the tool's adoption in CI/CD pipelines where developers expect zero-touch remediation.
Anthropic did not disclose how many partners have signed up, nor specific vulnerability-detection benchmarks for Mythos 5 on security tasks. The company also did not name which critical-infrastructure providers are involved. What's clear is the direction: the most capable model is being reserved for defense, with access controlled at the enterprise and partner level rather than offered broadly.
What to watch
Watch for which named security vendors publicly announce Mythos 5 integration and whether Anthropic publishes detection benchmarks comparing Mythos 5 against Opus 4.6 on CVE-finding tasks. Also track whether the human-approval requirement gets relaxed in a future release — that would signal confidence in autonomous patching.
Source: the-decoder.com
Originally published on gentic.news

Top comments (0)